Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.
2016-06-01T22:59:05.940
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citrix | xenapp | 7.5 | Yes |
Application | citrix | xenapp | 7.6 | Yes |
Application | citrix | xendesktop | 7.0 | Yes |
Application | citrix | xendesktop | 7.1 | Yes |
Application | citrix | xendesktop | 7.5 | Yes |
Application | citrix | xendesktop | 7.6 | Yes |
Application | citrix | xendesktop | 7.6 | Yes |
Application | citrix | xendesktop | 7.6 | Yes |
Application | citrix | xendesktop | 7.6 | Yes |
Application | citrix | xendesktop | 7.6 | Yes |